ankidroid / ankidroid/Anki-Android

The GA4 Measurement Protocol key

Abierto
#21,026 1 comentario 0 reacciones 0 asignados Ver en GitHub
Analytics Keep Open
Lenguaje dominante
Kotlin
Estrellas
11.8k
Forks
2.9k
Merge medio
2 d 3 h
PR fusionados (30 d)
171

Descripción

### Context
The GA4 Measurement Protocol `api_secret` is currently sourced from `local.properties` (`ANALYTICS_API_KEY`) or the `ANALYTICS_API_KEY` env var, with a `DUMMY_API_XXX` fallback so contributor builds compile.

### Question raised by @david-allison
> Only an issue with the build.gradle change, and that's mostly my ignorance/wanting reassurance.
>
> I believe in our prior implementation, the key wasn't obscured. Obscuring a publicly-facing analytics key is
> semi-understandable from the perspective of not wanting malicious clients, but it's unusual to me, as it's not a > private key.
>
> (For example, with Firebase, this would be a public credential on a website)
>
> If you'd be OK with deferring the conversation, shift it to an issue and merge at will!
> cc @mikehardy

### TODO
- [ ] Research how other OSS Android projects handle GA4 Measurement Protocol `api_secret` (Signal, K-9 Mail, F-Droid clients, etc.)
- [ ] Decide: keep obscuring, publish the key, or stand up a separate dev GA4 property
- [ ] Document the decision in the analytics package KDoc

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.